Skip to main content
AD Academy
Active Directory Basics
Beginner15 minLast updated: Topic 2 of 2

Domains, Trees and Forests

How AD's hierarchy is built.

Not read

What you will learn here

  • What a Domain, Tree and Forest are
  • How they relate to each other
  • Where OUs fit in the hierarchy

Worth reading first:What is Active Directory?

is built on a hierarchical model. The basic unit is the . Several Domains can join into a Tree, and several Trees together form a .

An interactive hierarchy from Forest through Tree and Domain to OU and objects. Color identifies the level type and labels keep the diagram understandable without color perception.

Main components

  • — a logical group of objects sharing a common security policy.
  • Tree — several Domains connected by Trust relationships and sharing a Schema.
  • — the top level: a collection of Trees sharing a Schema and Global Catalog.
  • OU () — a container inside a used to organize objects.
Forest: company.local
├── Tree: europe.company.local
│   ├── Domain: de.europe.company.local
│   └── Domain: fr.europe.company.local
└── Tree: asia.company.local
    └── Domain: jp.asia.company.local
text
Architecture and Theory — Under the Hood

The is the true Security Boundary, not the . An Enterprise Admin in a Forest can access any domain within it, so true separation between organizations requires a separate Forest.

  • Tree — A sequence of domains with a shared namespace (corp.com → il.corp.com).
  • Between domains in the same , an automatic Two-Way Transitive Trust exists.
  • An OU is a management unit ( + ), not a security boundary.
Practical Configuration (PowerShell / GUI)
# Add child domain
Install-ADDSDomain -NewDomainName "il" -ParentDomainName "corp.com" -DomainType ChildDomain

# Raise functional level
Set-ADDomainMode -Identity corp.com -DomainMode Windows2016Domain
Set-ADForestMode -Identity corp.com -ForestMode Windows2016Forest
powershell
Real-world Scenarios in the Organization
  • Common structure: One , one , and separation is done in OUs by site/department.
  • Separate for management environment (Red Forest / ESAE) in organizations with high security requirements.
Glossary and Quick Command Line
  • UPN — user@corp.com, the modern login name.
  • NetBIOS — CORP\user, the old name.
  • SYSVOL — A shared folder containing GPOs and scripts, replicated between DCs.

Check yourself

What is an OU in Active Directory?

Was this page helpful?